Description
An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download.
Published: 2026-10-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an OS command injection flaw in the configuration management subsystem of Brocade Fabric OS. When a configuration download is performed, the management daemon forwards user‑supplied strings unvalidated to an internal utility script, which interprets them in a shell command. A malicious or compromised configuration file can thus cause arbitrary operating system commands to run on the target switch, giving an attacker the ability to alter, delete, or exfiltrate data on the device.

Affected Systems

Affected products are Brocade Fabric OS obtained before version 9.2.2d and from 10.0.0 through 10.0.0a1. The vulnerability is present in all prior releases of Fabric OS 9.x and 10.x before the specified update releases.

Risk and Exploitability

The CVSS base score of 7.3 represents a high‑severity flaw. EPSS information is not reported, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to supply a configuration download request that includes a malicious relay host string or filename; the attacker typically needs a degree of control over the configuration file sent to the device or the ability to trigger the download as an administrator. The attack is likely to be local to the switch but can be triggered by a remote administrator who initiates the download with a malicious payload. Given the lack of a publicly available exploit, the actual threat remains moderate but the impact of successful exploitation is significant, allowing arbitrary OS command execution on the switch.

Generated by OpenCVE AI on October 8, 2026 at 05:29 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the Brocade Fabric OS 9.2.2d or 10.0.1 security update.
  • Restrict configuration download operations to trusted administrators and whitelist relay host names and filenames.
  • If an update cannot be applied immediately, disable the configuration download feature until the patch is deployed.

Generated by OpenCVE AI on October 8, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Brocade Fabric OS Command Injection via Configuration Download Parameter
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:34:36.578Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:55.843

Modified: 2026-10-08T04:17:55.843

Link: CVE-2026-87675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')